Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 2 vulnerabilities #22

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 658/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HOSTEDGITINFO-1088355
No Proof of Concept
medium severity 673/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 5.6
Prototype Pollution
SNYK-JS-MONGOOSE-1086688
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: mongoose The new version differs by 250 commits.
  • 5549f26 chore: release 5.12.2
  • 4b1aaac Merge pull request #10050 from SoftwareSing/fix-bulkwrite-with-timestamps-false
  • 3759f34 chore: address CR comments
  • 5ffbb8e fix(query): apply schema-level `select` option from array schematypes
  • 7d19c9f test(query): repro #10029
  • 4b0052e fix(schema): support setting `ref` as an option on an array SchemaType
  • 171c31f test(schema): repro #10029
  • 96f7905 fix(index.d.ts): make query methods return `QueryWithHelpers` so query helpers pass through chaining
  • 04f880f fix(index.d.ts): add back `Aggregate#project()` types that were mistakenly removed in 5.12.0
  • 9a3a7b4 style: fix lint
  • 91f003a Merge pull request #10053 from 418sec/1-npm-mongoose
  • 3ed44ff Merge pull request [Snyk] Fix for 45 vulnerabilities #1 from zpbrent/patch-2
  • 00e059d fix(index.d.ts): add `upserted` array to `updateOne()`, `updateMany()`, `update()` result
  • 003e477 add missing issue number
  • 0101ab8 fix(bulkwrite): make bulkWrite can work with `timestamps: false`
  • 9559c46 test(bulkwrite): repro #10048
  • 1bb97ba chore: update opencollective sponsors
  • 5888269 docs(mongoose+browser): fix broken links to info about `mongoose.Types`
  • 43b0cfa Merge branch 'master' of github.com:Automattic/mongoose
  • 03905c5 fix(index.d.ts): always allow setting `type` in Schema to a SchemaType class or a Schema instance
  • 422620b Merge pull request #10015 from Automattic/gh-9982
  • 7b14258 test(QueryCursor): fix tests from #10015
  • f2651d7 docs(transactions): introduce `session.withTransaction()` before `session.startTransaction()` because `withTransaction()` is the recommended approach
  • 61d313b chore: update opencollective sponsor logo

See the full diff

Package name: snyk The new version differs by 250 commits.
  • 3f52bdc Merge pull request #1669 from snyk/fix/dont-fail-on-request-big-payload
  • 47e106e fix: don't fail on request's big payload
  • 1228b55 Merge pull request #1624 from snyk/chore/cli-alert-improvement
  • fccd907 Merge pull request #1666 from snyk/chore/bump-cpp-test-timeout
  • 6772a3e Merge pull request #1649 from snyk/chore/deps-update
  • 89a7767 chore: update dependencies
  • eaf4915 test: wrap pagerduty await in try-catch, remove condition
  • 0576431 test: add pagerduty, check if test is running before attemmpting rerun
  • a08a938 chore: bump flaky cpp test timeout
  • ebb8dd7 Merge pull request #1656 from snyk/feat/protect-prime-time
  • 69cd590 test: fix flakey json output test
  • 3021bb2 Merge pull request #1663 from snyk/fix/upgrade-snyk-gradle-plugin
  • a988600 Merge pull request #1654 from snyk/feat/iac-experimental-terraform-support
  • b455497 feat: iac experimental tf support
  • 4848b7e chore: run tests in packages in CI
  • 3e7e99e feat: implement snyk protect
  • bb233f1 chore: enable prettier formatting in packages
  • fe0183d test: enable jest testing in snyk-protect workspace
  • 40ec817 test: test fixture for snyk protect
  • 7dfd3ea Merge pull request #1661 from snyk/test/fix-flake-with-dev-count-analysis
  • 02c99b8 test: remove tests previously migrated to jest
  • e203fd1 test: set timeout in beforeAll
  • d42f6d9 fix: update snyk-gradle-plugin to 3.13.2
  • 8cd9fbf Merge pull request #1662 from snyk/test/add-longer-timeouts

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant